LunarLoader — Malware Profile

LunarLoader is the loader component for the LunarWeb and LunarMail backdoors that has been used by Turla since at least 2020 including against a European ministry of foreign affairs (MFA). LunarLoader has been observed as a standalone and as a part of trojanized open-source software such as AdmPwd.

MITRE ATT&CK techniques (5)

Attributed threat actors

Read the full analysis on IntelFusions